Path-traversal vulnerability in QOS.CH Sarl Logback-classic on Java (logback-classic module) allows path-traversal vulnerability. More specifically, an
MDC-based discriminator value flows unsanitized into a nested
FileAppender path, letting an attacker who influences that MDC value
(e.g. via an HTTP header)
create and append log files outside the intended directory.
This issue affects Logback-classic: from 0.9.14 through 1.6.2.
CVSS
No CVSS.
References
| Link | Resource |
|---|---|
| https://logback.qos.ch/news.html#1.6.3 |
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-14 15:17
Updated : 2026-08-26 16:39
NVD link : CVE-2026-19880
Mitre link : CVE-2026-19880
CVE.ORG link : CVE-2026-19880
JSON object : View
Products Affected
No product.
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
